Nicolas Krassas[verified]@DinosnPoC
A functional PoC and GitHub repository for the CVE-2026-6807 XXE vulnerability in Grassmarlin have been released.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The NSA’s retired GrassMarlin OT network analysis tool is being actively abused in the wild through an unpatched XML External Entity vulnerability, leaking sensitive SCADA discovery data.
Lyrie.ai[verified]@lyrie_aiDisclosure
The article reports CISA’s flagging of CVE‑2026‑6807, an XXE vulnerability in the GrassMarlin tool that could lead to data theft. No exploitation details, patches, or PoC references are provided.
Lyrie.ai[verified]@lyrie_aiGeneral
The snippet references CVE-2026-6807, highlighting an XXE-based data theft flaw in GrassMarlin, but provides no details on exploitation or patches.
Lyrie.ai[verified]@lyrie_aiDisclosure
The CISA advisory announces a critical XXE vulnerability (CVE‑2026‑6807) in the obsolete NSA tool GrassMarlin, noting the lack of a vendor patch.
Lyrie.ai[verified]@lyrie_aiDisclosure
The snippet announces CVE-2026-6807, an XXE vulnerability in GrassMarlin, highlighting its potential to expose NSA’s archived OT security weapon to data theft, without providing proof‑of‑concept details, exploitation tools, or patches.
ThreatCluster[verified]@threatclusterPoC
CISA has issued a warning about CVE-2026-6807, an XXE data‑theft flaw in NSA GrassMarlin with a public PoC available, but no patch exists because the product is EOL.
Security Arsenal, LLC[verified]@SecurityAr58409Patch
The text announces CISA’s flagging of CVE-2026-6807 (NSA GRASSMARLIN XXE) and supplies a detection and hardening guide, providing mitigation steps but no exploit or patch details.